# Date filter for logstash

**URL:** <https://discuss.elastic.co/t/date-filter-for-logstash/120203>\
**Category:** Logstash\
**Created:** [February 16, 2018, 2:55pm UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203 "2018-02-16T14:55:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mugil1988](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Post date:** [February 16, 2018, 2:55pm UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203/1 "2018-02-16T14:55:16Z")

</div>

Hi all,

We are able to parse the date in the log file using ISO8601 format.

But we are using the same format in date filter..

Not able to use the log date as logstash timestamp in kibana.

Log date format - 2018-02-16T16:34:59.906-05:30

Kindly some one tell me what exactly needs to use in date filter?

Regards,  
Msd

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 16, 2018, 3:36pm UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203/2 "2018-02-16T15:36:56Z")

</div>

What does an example document look like? Copy/paste the raw JSON from Kibana's JSON tab.

---

<div class="post-metadata">

**Author:** ![mugil1988](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Post date:** [February 17, 2018, 4:24am UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203/3 "2018-02-17T04:24:26Z")

</div>

@magnusbaeck

Hi Magnus..  
{

"\_index": "logstash-Sample-ACC-2018.02.18",

"\_type": "log",

"\_id": "AWGe-HzBk5yJzwLFmFg1",

"\_version": 1,

"\_score": null,

"\_source": {

```
"@timestamp": "2018-02-18T01:15:10.886Z",

"offset": 9425,

            "reqpayload": " "

"@version": "1",

"input_type": "log",

"beat": {

  "hostname": "EKL",

  "name": "EKL",

  "version": "5.5.1"

},

```

The value in the time stamp is based on file modification time..

But date in the log file is in below format.

sample log:

Request[2017-09-07T10:39:06.133+05:30] "

"LOS16062\<message\_type\_cd\>KB015\</message\_type\_cd\>"

Not able to parse and use this date as a logstash timestamp

Kindly let me know the date filter to parse the log date?

Regards,  
Mugilvannan

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 19, 2018, 7:03am UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203/4 "2018-02-19T07:03:59Z")

</div>

Your example document doesn't contain any timestamp except `@timestamp`. What timestamp do you want to parse?

---

<div class="post-metadata">

**Author:** ![mugil1988](https://avatars.discourse-cdn.com/v4/letter/m/f14d63/32.png) [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Post date:** [February 19, 2018, 7:16am UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203/5 "2018-02-19T07:16:35Z")

</div>

@magnusbaeck

Now everything is working...I have started logstash with old conf file... Thanks a lot..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2018, 7:16am UTC](https://discuss.elastic.co/t/date-filter-for-logstash/120203/6 "2018-03-19T07:16:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
